PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
References
Configurations
History
21 Nov 2024, 04:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/jjanku/podofo/commit/ada821df68fb0bf673840ed525daf4ec709dbfd9 - | |
References | () https://github.com/mksdev/podofo/commit/1400a9aaf611299b9a56aa2abeb158918b9743c8 - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CIC2EXSSMBT3MY2HY42IIY4BUQS2SVYB/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTJ5AAM6Y4NMSELEH7N5ZG4DNO56BCYF/ - | |
References | () https://research.loginsoft.com/bugs/null-pointer-dereference-vulnerability-in-setsource-podofo-0-9-6-trunk-r1967/ - Exploit, Third Party Advisory | |
References | () https://sourceforge.net/p/podofo/tickets/40/ - Exploit, Third Party Advisory |
07 Nov 2023, 03:13
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
27 Oct 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2019-02-26 23:29
Updated : 2024-11-21 04:51
NVD link : CVE-2019-9199
Mitre link : CVE-2019-9199
CVE.ORG link : CVE-2019-9199
JSON object : View
Products Affected
podofo_project
- podofo
fedoraproject
- fedora
CWE
CWE-476
NULL Pointer Dereference